//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1724 EDT (UTC-04), Sunday 24 May 2026

Contents

9 stories from 37 sources across 33 organizations


KEY JUDGMENTS

Russia is simultaneously expanding intelligence posture against Western collection assets across three domains: co-orbital positioning against an ICEYE satellite supporting Ukraine, ground-based SIGINT expansion in Cuba, and bulletproof hosting infrastructure for hacktivist campaigns. At least one Western attribution paired with a punitive measure against these operations is likely by October 1. High confidence rests on the Dutch Fiscal Intelligence and Investigation Service (FIOD) seizure and EU council cycles providing independent forcing events within the window. A publicly disclosed attack degrading a Western commercial satellite is very unlikely through August.

Gabbard's forced departure tightens White House control over war-related assessments, but US offensive strikes against Iran remain unlikely by October, absent a mass-casualty attack on US personnel or an Iranian nuclear breakout. Low confidence reflects reliance on a single unnamed Reuters source. Formal charges or named sanctions targeting Kali365 or Islamic Revolutionary Guard Corps (IRGC)-affiliated Nimbus Manticore operators are unlikely by year-end.

At least one EU member state will likely restrict US-based platforms for government communications before mid-2027, driven by Russian phishing exploitation of Signal and digital sovereignty concerns. Russia's multi-domain positioning may serve principally as strategic bargaining leverage; any Cosmos satellite closing within one kilometer of ICEYE-X36 would alter this assessment.


Adversary Intelligence

FBI Warns of Kali365 Phishing-as-a-Service Platform Targeting Microsoft 365 at Scale

BLUF: Disruption of Kali365 within six months of the FBI's May 21 advisory is unlikely, and the platform's token-sharing model means compromised tenants stay exposed even if the service folds.

The FBI issued a public service announcement on May 21 about Kali365, a phishing-as-a-service platform first observed in April and distributed via Telegram, that captures Microsoft 365 Open Authorization (OAuth) tokens through device-code flows rather than stealing credentials 1. Victims are directed to a legitimate Microsoft verification page to enter an attacker-supplied code, unknowingly authorizing access; captured tokens then enable persistent entry to Outlook, Teams, and OneDrive without further MFA challenges 12. Arctic Wolf Labs, which obtained access to the Kali365 system, reported the platform charges $250 for 30 days or $2,000 annually and generates AI-driven lures impersonating Adobe, DocuSign, and SharePoint across dozens of languages 23. Arctic Wolf additionally found Kali365 supports adversary-in-the-middle (AitM) session capture alongside device code flows, and enables a full post-compromise workflow including mailbox access, contact harvesting, lateral phishing, and BEC keyword monitoring 23. Captured tokens are stored on the platform and made available to affiliates, allowing reuse by actors who played no part in the original phishing campaign 23.

Analyst Note: Disruption of Kali365 infrastructure within six months of the FBI's May 21 advisory is unlikely. Moderate confidence reflects documented precedent for Phishing-as-a-Service (PhaaS) platforms migrating ahead of legal action, offset by incomplete visibility into any parallel law enforcement operations already targeting the platform. The FBI/Internet Crime Complaint Center (IC3) Public Service Announcement (PSA) is the sole original source; secondary coverage adds no independent corroboration. FBI advisories of comparable specificity have, in analogous PhaaS cases, preceded platform disruption, and Kali365 may not prove the exception. Captured refresh tokens remain valid until administrators explicitly revoke individual sessions, and enterprise security teams should treat device code flow restriction as a standing control regardless of whether Kali365 survives enforcement.

Sources:

1: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens - FBI / Internet Crime Complaint Center (IC3)

2: FBI warns about fast-growing phishing kit targeting Microsoft 365 users - CyberScoop

3: FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks - The Record (Recorded Future News)

FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale - The Register

Dutch Police Seize Two Pro-Kremlin Bulletproof Hosting Providers Under Sanctions Laws

BLUF: Dutch prosecutors likely file formal charges against at least one suspect within 12 months, testing whether EU sanctions law can durably disrupt Russian-aligned hosting front companies enabling NoName057(16) operations.

FIOD on May 22 arrested Youssef Z., 57, director of WorkTitans B.V., and Andrey N., 39, founder of MIRhosting, seizing roughly 800 servers from data centers in Dronten and Schiphol-Rijk for alleged EU sanctions violations 12. FIOD alleges WorkTitans, which offered hosting under the brand THE.Hosting, operated as a front for Stark Industries after the EU sanctioned that firm on May 20, 2025, while MIRhosting supplied connectivity routed through major Amsterdam and Frankfurt internet exchanges 21. De Volkskrant, citing confidential information, reported both firms topped the list of networks used in pro-Russian Distributed Denial of Service (DDoS) attacks on Danish government organizations during November 2025 municipal elections, with Danish authorities separately linking WorkTitans to NoName057(16) 12. Both suspects were questioned and released pending ongoing forensic analysis of seized servers, devices, and administrative records 12.

Analyst Note: Formal criminal charges against at least one of the two suspects are likely within 12 months of the May 22 seizure. Moderate confidence reflects 800 seized servers, devices, and administrative records cross-referenced against Danish attribution directly linking WorkTitans to NoName057(16) election-targeting campaigns, though all four reporting outlets converge on the single FIOD press release without independent investigative access. Dutch prosecutors may instead pursue administrative penalties if they determine the infrastructure transfer reflects commercial opportunism rather than the deliberate sanctions evasion Dutch criminal liability requires. Charges that succeed allow EU sanctions coordinators to extend the FIOD enforcement model to other Stark-linked entities. Failed prosecution cements post-sanction corporate restructuring as a durable legal shield.

Sources:

1: Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions - NL Times

2: Netherlands seizes 800 servers of hosting firm enabling cyberattacks - BleepingComputer

FIOD houdt twee verdachten aan wegens overtreding sanctiewetgeving - FIOD (Dutch Fiscal Intelligence and Investigation Service)

How a consultant and a concert pianist from the Netherlands were arrested on suspicion of aiding NoName057(16) - DataBreaches.Net

Netherlands Cracks Down on Russian-Linked Cybercrime with Major Server Seizure - News4Hackers

Check Point Tracks Iranian APT Nimbus Manticore Expanding Into Europe With AI-Assisted Malware

BLUF: Formal Western indictments or sanctions naming Nimbus Manticore operators remain unlikely through end of 2026, leaving European aviation and software defenders to absorb the cost of the group's AI-enabled tradecraft alone.

Check Point Research reported on May 22 that Nimbus Manticore (UNC1549), an IRGC-affiliated group, ran three campaign waves from February through April 2026 targeting aviation, software, defense, and telecom organizations across the United States, Europe, and the Middle East, activity Check Point tied to the onset of Operation Epic Fury, the U.S. military campaign against Iran launched February 28, 2026 123. The group replaced its MiniJunk toolset with a new backdoor, MiniFast, delivered via AppDomain hijacking; Check Point attributed its modular structure and excessive error handling to AI-assisted development practices, and the group additionally deployed a Trojanized Zoom installer via fake meeting-invitation phishing lures 12. A third wave in April used Search Engine Optimization (SEO) poisoning, a first for this actor, through a counterfeit SQL Developer download site (getsqldeveloper[.]com) that ranked high on Bing and DuckDuckGo, with campaign files carrying valid SSL.com digital signatures under two certificate names: Gray Matter Software S.R.L. and Kirubel Kerie Negeya 12.

Analyst Note: Formal indictments or sanctions naming Nimbus Manticore operators are unlikely by end of 2026. Analytic confidence is low, grounded in the historical pattern of IRGC-affiliated operators escaping formal proceedings despite clear attribution. The diplomatic calculus between Washington and Tehran removes political incentive for escalatory legal action even as attribution sharpens. Reporting rests on a single Check Point investigation amplified by two outlets without independent sourcing. MiniFast's modular architecture and verbose error handling more plausibly reflect deliberate obfuscation tradecraft than confirmed AI integration. Continued SSL.com certificate abuse and SEO poisoning extend dwell time, and European aviation and software firms cannot defer contract screening for IRGC-linked entities against a sanctions designation unlikely to arrive before year-end.

Sources:

1: Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research

2: Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict - Malware News

3: Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict - MalwareTips Forums

WSJ Reports China and Russia Tripled Intelligence Personnel in Cuba With SIGINT Facilities Targeting US Military Bases

BLUF: Havana is very unlikely to curb Chinese or Russian SIGINT activity on the island by year-end 2026, forcing Washington to absorb the collection threat through defensive measures rather than diplomatic pressure.

Unnamed U.S. officials told the WSJ Friday that the Cuban-based facilities are positioned to intercept communications from two Florida military headquarters overseeing Middle East and Latin American operations, with intelligence personnel nearly tripling since 2023 12. In December 2024, Center for Strategic and International Studies (CSIS) separately identified at least 12 Chinese SIGINT-linked facilities across four locations in Cuba, including one in Santiago de Cuba roughly 70 miles from Guantánamo Naval Base 1. On May 14, CIA Director Ratcliffe traveled to Havana and met with Cuban Interior Minister Lázaro Álvarez Casas and Raulito Rodríguez Castro, grandson of former President Raúl Castro, stating Cuba could no longer serve as a platform for adversaries advancing hostile agendas in the hemisphere 1. China's MFA spokesperson Lin Jian denied the allegations, describing Beijing's cooperation with Cuba as "legitimate, transparent, and in accordance with international law" 1.

Analyst Note: Cuba is very unlikely to take any publicly verifiable step to constrain Chinese or Russian SIGINT operations on its territory by year-end 2026. Ratcliffe's May 14 Havana visit produced no announced concession. Cuba's reported financial dependence on Chinese hosting payments eliminates any economic incentive to comply. The Beijing investment may instead serve primarily as strategic positioning to deter US military options against Havana rather than as an active collection platform against Florida commands. Low confidence attaches given reporting rests entirely on unnamed US officials via a single outlet with no independent corroboration. The Pentagon's June 2026 National Defense Authorization Act (NDAA)-mandated report becomes the policy trigger for accelerated counter-SIGINT hardening at USCENTCOM and USSOUTHCOM.

Sources:

1: U.S. Sounds Alarm: Rising Russian and Chinese Espionage in Cuba - Cuba Headlines

2: WSJ: Russia and China Expand Intelligence Operations in Cuba - Pravda Ukraine

U.S. Warns of Growing Russian and Chinese Spying in Cuba - Wall Street Journal

Allied Intelligence

European Governments Move to Replace Signal With Sovereign Encrypted Messaging Apps Amid State-Hacker Phishing Concerns

BLUF: Sovereign Matrix deployments will harden internal European traffic against Russian phishing, but formal Signal prohibitions by at least two of the four governments before June 2027 remain unlikely given unresolved diplomatic use cases.

Germany, France, Belgium, and Poland are developing and adopting sovereign encrypted messaging platforms to replace Signal and WhatsApp for internal government communications, as reported on May 22 by Tom Uren's 'Srsly Risky Biz' newsletter, a single piece cross-published simultaneously on both Lawfare and news.risky.biz, not two independent reports. 12 Both reported drivers remain: Russian intelligence-attributed phishing campaigns exploiting Signal's linked devices feature, and European concern over US-platform dependence. 12 Germany, France, and Belgium have deployed Matrix-protocol-based systems (Germany via ZenDiS/OpenDesk, France via Tchap, Belgium via BEAM) serving hundreds of thousands of government employees; Poland's sovereign alternative is specifically named mSzyfr Messenger, developed by the Ministry of Digital Affairs and NASK and launched in March 2026. 12 The closed intra-government nature of these deployments leaves Signal in continued use for senior officials conducting diplomacy with external parties. 12

Analyst Note: Matrix deployments narrow Russian intelligence access to internal networks but leave senior officials exposed: no sovereign platform bridges trusted networks across governments, and diplomatic communication continues on Signal. At least two of the four governments formally prohibiting Signal for sensitive internal use by June 2027 is unlikely. None has signaled intent to ban a tool it cannot enforce externally, and walled-garden deployments are complements, not replacements. The phishing rationale may be cover for a sovereignty push driven by transatlantic friction; if so, the transition is durable regardless of the security case. Low confidence attaches, resting on a single reporting thread without corroborating government documentation. Allied agencies treating Signal as the default channel with European counterparts should plan alternatives.

Sources:

1: Politicians to Ditch Signal for Homegrown Apps - Lawfare

2: Srsly Risky Biz: Politicians to Ditch Signal for Homegrown Apps - Risky Business Newsletter

Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative - The Register

NATO ISR Force Conducts First RQ-4D Phoenix Drone Operations From Norway Under Agile Combat Employment

BLUF: Ørland's hosting of the NATO variant of the Global Hawk unmanned aerial vehicle (RQ-4D) marks NATO's shift from showcasing Agile Combat Employment to institutionalizing it, extending persistent Intelligence, Surveillance and Reconnaissance (ISR) over the Northern Fleet's bastion with reduced reliance on Sigonella.

On May 21, the NATO Intelligence, Surveillance and Reconnaissance Force conducted its first RQ-4D Phoenix remotely piloted aircraft operations from Norwegian territory, flying from Ørland's 132 Air Wing under the Agile Combat Employment concept 12. NATO confirmed this was only the third time the system has operated outside its permanent base at Italian Air Force Base Sigonella 12. Before the operation, NATO Intelligence, Surveillance and Reconnaissance Force (NISRF) Training Centre personnel trained 132 Air Wing support staff to integrate procedures and capabilities on site 12. NISRF Commander Brigadier General John B. Creel and 132 Air Wing Base Commander Colonel Ole Marius Tørrisplass each issued on-record statements describing the deployment as a demonstration of Alliance ISR flexibility and shared collective defence readiness 12.

Analyst Note: The Ørland deployment places persistent RQ-4D surveillance within range of Northern Fleet operating areas, forcing Russian planners to account for expanded ISR coverage along Kola Peninsula approaches and Norwegian Sea transit corridors. As only the third departure from Sigonella, the sortie marks a measurable advance in operationalizing Agile Combat Employment (ACE) beyond its conceptual phase. The preceding on-site training by NISRF Training Centre staff points to deliberate capacity-building at 132 Air Wing, suggesting future deployments will require shorter lead times. The single source, an official NATO press release carrying no independent corroboration, leaves open that the sortie was primarily a strategic communications event with no active ISR tasking against Russian targets.

Sources:

1: First RQ-4D Phoenix Operations in Norway mark NISRF Milestone - GlobalSecurity.org

2: NATO ISR Force conducts First RQ-4D Phoenix operations from Norway under Agile Combat Employment - Defence Industry Europe

First RQ-4D Phoenix Operations in Norway mark NISRF Milestone - NATO Allied Command Operations

The first landing of a NATO RQ-4D Phoenix unmanned aerial vehicle in Norway - Pravda NATO

Counterintelligence & Tradecraft

Greek Court Convicts Azerbaijani Man of Espionage for Photographing NATO Souda Naval Base

BLUF: Public attribution of the Azerbaijani convict to a named foreign service remains unlikely through end of 2026, leaving the Souda and Cyprus cases tactically linked but diplomatically unresolved for Athens.

A Greek court on May 20 sentenced an Azerbaijani national, who had entered on a Polish residence permit, to seven years and one month for espionage at Souda Bay naval base, a Greece-US-NATO facility in western Crete 123. Arrested in June 2025 after a joint police-intelligence operation, he had occupied a hotel room overlooking the base and was found with a telephoto camera, tripod, USB storage media, and encryption software on his laptop 123. Reuters reported 23 videos and nine photographs of a docked Greek Navy frigate as key trial evidence; the Athens Times cited over 5,000 photographs total on his devices 21. His lawyer told Reuters he "did not intend to spy" and he has appealed; Greek authorities are examining possible links to the concurrent arrest of a British national in Cyprus on espionage and terrorism charges 23.

Analyst Note: Greek and European authorities are unlikely to publicly establish a direct operational link to a named foreign intelligence service by end of 2026. We assess this with high confidence: intelligence services that privately resolve attribution rarely surface it while appeals remain active and diplomatic equities are unresolved, and the court record names no handler. Matching camera systems and a shared transmission application with the concurrent Cyprus arrest suggest coordinated tasking infrastructure, though that pattern, sourced to Reuters and the Athens Times alone, falls short of public attribution. The same court record fits a commercial intelligence broker equally well, with persistent denial consistent with broker compartmentation rather than state tasking. Confirmed state attribution would shift the counterintelligence burden at Souda from generic to targetable, enabling NATO partners to impose diplomatic costs and calibrate EYP intelligence-sharing.

Sources:

1: Azerbaijani Spy Sentenced in Souda Case - Athens Times

2: Greek court finds Azerbaijani man guilty of spying for monitoring military base - Cyprus Mail

3: Greece jails Azerbaijani man over spying on base - Hurriyet Daily News

Azerbaijani man gets jail time for Greek naval base espionage - Baird Maritime

IC Oversight & Authorities

Reuters Reports White House Forced Gabbard Out Over Iran War Opposition as CIA Conflict Deepened

BLUF: Removing the intelligence community's leading non-interventionist voice tightens White House control over Iran assessments but leaves U.S. offensive strikes unlikely before October 1, 2026.

Reuters reported on May 22, citing an unnamed source familiar with the matter, that the White House forced Gabbard out and had "been unhappy with her for quite some time" 1. Both Gabbard and White House spokesperson Davis Ingle publicly cited her husband Abraham Williams' recent rare bone cancer diagnosis; her resignation takes effect June 30 23. The Reuters source linked White House displeasure to the activities of her Director's Initiatives Group and her non-interventionist stance on Iran, and said she had been sidelined from war-related discussions 23. Gabbard's chief of staff Alexa Henning publicly disputed the Reuters account as false, and Principal Deputy Director of National Intelligence (DNI) Aaron Lukas is set to assume the acting director role upon her departure 32.

Analyst Note: U.S. offensive military strikes against Iran remain unlikely by October 1, 2026. Gabbard's departure removes the IC's most prominent non-interventionist voice, but leadership changes alter the tenor of internal debate without dissolving the operational, diplomatic, and escalation-management constraints that make a strike order costly. Sidelining a Senate-confirmed director over Iran policy signals war-related intelligence will now flow through more aligned channels. The cancer diagnosis may be the genuine driver, with the Reuters source reflecting a disgruntled insider rather than the administration's actual calculus. Low confidence: the entire account rests on one unnamed Reuters source that Gabbard's chief of staff publicly disputed. A YES outcome forces Gulf partners and allied defense planners onto a war-footing contingency timeline they can otherwise defer well past June.

Sources:

1: White House Forced Top Spy Gabbard to Resign, Source Says - Reuters (via U.S. News & World Report)

2: Reuters Reports Trump WH 'Forced' Tulsi Gabbard to Resign - Mediaite

3: White House forced Tulsi Gabbard to resign, Reuters reports - Prism News

IC Technology & Surveillance

Four Russian Military Satellites Maneuver Within Striking Distance of ICEYE Radarsat Supporting Ukraine

BLUF: Russia's co-planar positioning leaves ICEYE-X36 effectively hostage to Moscow's discretion, though a kinetic, directed-energy, or electronic attack remains unlikely by end of August 2026 absent a sharper escalation trigger.

Four Russian Cosmos satellites, 2610 through 2613, maneuvered into co-planar orbit with ICEYE-X36 between May 14 and May 20, according to Integrity ISR analyst Greg Gillinger 12. Each satellite raised its inclination 0.8°, from 97.0° to 97.8°, at an estimated delta-v cost of 105–106 m/s, which Gillinger characterized as atypical for Earth observation or communications satellites 1. The four now orbit within 2.5 kilometers of ICEYE-X36's altitude with cross-track separations of 0.5 to 22 kilometers, and a fifth satellite, Cosmos 2614, appears to be completing the same maneuver 12. Tom's Hardware, citing Ars Technica, reported that unnamed U.S. officials assess some of the Cosmos satellites as connected to an anti-satellite weapons program, while a retired U.S. military space official told Ars Technica the maneuvers may represent Russia 'rattling a dull saber' rather than a genuine operational threat 3.

Analyst Note: Russia has cleared the most fuel-expensive barrier to co-orbital action against ICEYE-X36, with up to five Cosmos satellites now co-planar and within 2.5 kilometers of its altitude. A kinetic, directed-energy, or electronic warfare strike by end of August 2026 is nonetheless unlikely given Moscow's sustained preference for coercive demonstration over irreversible action against Western commercial assets. At 90 kilograms, ICEYE-X36 lacks propellant for meaningful evasion, leaving operation contingent on Russian restraint. The maneuvers may instead reflect persistent surveillance of Ukraine's Synthetic Aperture Radar (SAR)-tasking patterns and a test of NATO space domain awareness. This assessment carries low confidence, resting on a single self-published commercial evaluation with no independent corroboration of Cosmos capabilities or command intent. Ukraine's near-real-time targeting access and Western commercial space policy both hinge on whether that restraint holds through August.

Sources:

1: Is Russia Maneuvering to Threaten an ICEYE Satellite? - Integrity ISR

2: Russian Satellites Maneuver Into Co-Planar with Finnish SAR Satellite Supporting Ukraine, Integrity ISR Analysis Finds - EIN Presswire

3: Commercial satellite supplying intel to Ukraine is cornered by four Russian spacecraft - Tom's Hardware

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE